Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

W32/Wozer.worm@MM

Nov 18, 2003 12:03AM PST

Internet Worm Information
Discovery Date: 11/14/2003
Origin: Unknown
Length: 23,040 bytes
Type: Internet Worm
Description Modified: 11/17/2003 11:10 AM (PT)

This is a detection for an internet worm that spreads by email, IRC and network shares.


After execution, the worm copies itself to %sysdir% as Explore.exe and eCard.zip. The following registry key is changed to run the virus at startup:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" = "Explorer.exe Explore.exe"

More: http://vil.nai.com/vil/content/v_100824.htm

Discussion is locked